Cloudflare will begin issuing quantum-safe TLS certificates, the company announced, making it one of the first major internet infrastructure firms to deploy encryption designed to withstand attacks from future quantum computers.
The certificates use post-quantum cryptography algorithms, which security experts say will eventually be needed to protect data that could be harvested now and decrypted later once powerful quantum machines become available.
TLS certificates are the digital documents that power the padlock icon in web browsers, verifying a site's identity and encrypting traffic between a user and a server. Today's certificates rely on mathematical problems that quantum computers could theoretically solve in seconds.
The National Institute of Standards and Technology finalized its first post-quantum cryptography standards in August 2024, giving companies a formal blueprint to begin migrating. Cloudflare's move follows that guidance and signals the start of a broader industry shift.
"The threat is not theoretical forever," Cloudflare said in its announcement, noting that adversaries could already be collecting encrypted data today with the intent of breaking it later, a strategy known as "harvest now, decrypt later."
Cloudflare operates one of the world's largest content delivery networks, handling traffic for roughly 20 percent of the web. Its decision to issue quantum-safe certificates could pressure other certificate authorities and cloud providers to follow suit.
The company said the rollout will be gradual, with compatibility testing across browsers and devices before broad availability. Older clients that do not support the new algorithms will continue to receive traditional certificates during the transition.
Experts have warned that migrating the internet's certificate infrastructure is a years-long process. Browsers, operating systems, and server software all need updates before quantum-safe certificates can work universally.
Cloudflare did not specify an exact date for general availability but said it is working with partners across the industry to ensure a smooth transition. The company has previously tested post-quantum key agreement in its TLS connections, a related effort that began in 2022.
The shift matters beyond tech companies. Banks, hospitals, and government agencies rely on TLS to protect sensitive data, and any weakness in that chain could expose records for decades. Security researchers have urged organizations to begin inventorying their cryptographic systems now.
Quantum computers powerful enough to break RSA and elliptic-curve cryptography do not yet exist. But the timeline for building them is uncertain, and experts say the migration must start well before that day arrives.
Cloudflare's announcement puts the company ahead of most competitors in the race to quantum-safe encryption, though rivals including Google and Microsoft have launched similar pilot programs. The coming months will show whether the rest of the industry keeps pace.